The city of Columbus, Ohio received a ransomware attack that affected approximately 500,000 residents, leaving their personal data and information stolen. Systems were quickly taken offline once the breach was discovered, however that didn't stop the criminals from stealing the data and putting it on the dark web. It was noted that to avoid these kinds of data breaches there needs to be micro-segmentation on the networks to avoid lateral infections. The city filed a lawsuit against a cybersecurity expert who exposed the data breach to the public.While the lawsuit was later dropped, it is noted that this kind of response sets a worrying precedence for those in the future who could shed light upon similar events.
Published by Dikli Rathnayake on informationsecuritybuzz.com, on November 5th 2024, the actual attack occurred in July 2024. The article leaves an objective impression stating true facts about events that happened, and stresses the importance of transparency for these incidents, and advocates for stronger cybersecurity practices.
In this article, European diplomats were targeted with a phishing email that once opened, executed malware. A spear-phishing email, designed for specific high level targets, contained a .zip file titled "The EXPO Exhibition in Japan in 2025.zip" on OneDrive, which obviously fooled those people into thinking it was a legitimate email. These diplomats should have verified that it was the correct file from a proper source, all it takes is a single person getting careless for something like this to work.
Published by Ravie Lakshmanan in The Hacker News on November 7th 2024, these events that transpired should serve as a warning to those who could potentially be a victim to inadvertently releasing sensitive information. The article does point out the political affiliation of the hacker-group behind this attack, citing them to be Chinese-backed, and primarily as a threat to the Japanese and United States. TheHackerNews does not have any known affiliations with the United States Government or any international organization, it is just an enthusiast website. This leaves me to believe it presents an objective take on the events that transpired.
Dilki Rathnayake. (2024, November 5). 500,000 Affected in Columbus Data Breach, Followed by Lawsuit Against Security Researcher. Information Security Buzz. https://informationsecuritybuzz.com/columbus-data-breach-lawsuit-sec-resea/
News, T. H. (2024, November 7). China-Aligned MirrorFace Hackers Target EU Diplomats with World Expo 2025 Bait. The Hacker News. https://thehackernews.com/2024/11/china-aligned-mirrorface-hackers-target.html